Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@staff.aruba.it.
The latest stored availability evidence still shows the domain reachable; 19 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
b-buc[.]it
b-buc.it için kimlik avı ve güvenlik kontrolü
“Maintenance”
b-buc.it — Bilinen son aktif (HTTP 200). Kanıt özeti: VirusTotal 14/91 (alphaMountain.ai, BitDefender, CRDF, ESET, Forcepoint ThreatSeeker); Google Safe Browsing flagged; PhishDestroy score 100/100. Kayıt kuruluşu: Aruba s.p.a.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
Analysis of the domain b-buc.it shows that it has been active since its registration on 9 May 2019 through Aruba s.p.a. The authoritative name servers dns.technorail.com, dns2.technorail.com and dns3.arubadns.net resolve the name to the IPv4 address 31.11.36.13. The domain appears on the PhishDestroy blocklist, indicating that at least one security‑focused feed has classified it as malicious. Google Safe Browsing also marks the site for social engineering, a label consistent with phishing‑related activity. VirusTotal scans have returned three positive detections out of ninety‑five submitted security engines, providing additional independent confirmation of suspicious behavior. No public SSL certificate details, HTTP response codes, or page title information are currently available, so the exact nature of the hosted content cannot be verified from the present data set. The lack of such telemetry leaves the specific phishing vector—whether credential harvesting, account takeover, or other social‑engineering technique—undetermined. Nevertheless, the convergence of blocklist inclusion, Safe Browsing warning, and multiple vendor detections establishes a high confidence that b-buc.it is being used for phishing. Defenders should add the IP address 31.11.36.13 and the domain name to network‑level denylists, enforce DNS filtering that incorporates the PhishDestroy feed, and monitor outbound traffic for connections to the host. Continuous re‑scanning with VirusTotal or similar multi‑engine platforms is recommended to capture any evolution of the payload. Analysts should also retrieve the site’s HTTP response and TLS certificate when possible to enrich the profile and confirm the exact phishing campaign employed.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Tehdit İstihbaratı Çapraz Referansı · source references
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of b-buc.it · checked Jul 20, 2026
Kanıtlar ve Dış Raporlar
PD-20260720-994EF0 Recipient: abuse@staff.aruba.it Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin